The Sarbanes-Oxley Act (SOX) is a US federal law passed in 2002 after a series of major accounting scandals. It requires public companies to maintain internal control over financial reporting, has executives personally certify their financial reports, and, for larger companies, requires an outside auditor to attest to those controls. It also created the Public Company Accounting Oversight Board (PCAOB) to oversee auditors of public companies. This entry is an overview for buyers, not legal or accounting advice.
At a glance
- SOX applies mainly to companies with securities registered with the US Securities and Exchange Commission (SEC), including many foreign companies listed in the US.
- Section 302 makes the CEO and CFO certify each periodic report and their responsibility for controls.
- Section 404 requires an annual management assessment of internal control over financial reporting; larger filers also need an auditor’s attestation.
- IT general controls, such as access, change management and operations for financial systems, are a core part of the audit.
- Vendors that run financially significant systems usually provide SOC 1 reports so their controls can be relied on.
What problem it solves
Investors depend on financial statements being accurate. The scandals that led to SOX showed that executives could sign off on numbers without being accountable, and that weak internal controls let errors and fraud go undetected. SOX makes leaders personally responsible for the reports, forces companies to document and test their controls, and puts auditors under independent oversight.
For IT, the effect is concrete. The systems that produce financial numbers, such as ERP, billing, payroll, databases and the infrastructure under them, need controls over who has access, how changes are approved and tested, and how jobs and backups run. Management tests those controls each year, and at larger companies the external auditor does too.
How it works
Scoping. The company identifies significant accounts, the business processes behind them and the IT systems those processes rely on.
Controls. For each process, the company documents key controls. On the IT side these are IT general controls: user provisioning and access reviews, privileged access, change management, segregation of duties, job scheduling, backup and incident handling.
Testing and remediation. Management tests the controls during the year, often with internal audit or outside advisors, and fixes deficiencies before year end.
Assessment and certification. Management states its conclusion on the effectiveness of controls in the annual report, and executives certify each quarterly and annual report. For larger filers, the external auditor issues its own opinion on internal control.
Service organizations. Where a vendor performs part of a control, the auditor typically relies on a SOC 1 report on that vendor, and the company must operate the complementary user entity controls the report lists.
Filer categories
SOX has no certification levels, but its heaviest requirement depends on the company’s SEC filer category, which is based on public float and, for smaller companies, revenue.
| Category | Who it covers | Section 404 requirement | What it typically shows |
|---|---|---|---|
| Large accelerated filer | Largest public companies by public float | Management assessment plus external auditor attestation (404(b)) | Annual report with management’s report and the auditor’s opinion on internal control |
| Accelerated filer | Mid-sized public companies, excluding certain low-revenue smaller reporting companies | Management assessment plus external auditor attestation | Same as above |
| Non-accelerated filer | Smaller public companies, including many low-revenue smaller reporting companies | Management assessment only (404(a)) | Management’s report; no auditor attestation on internal control |
| Emerging growth company | Newly public companies that qualify, for a limited period | Management assessment; auditor attestation not required during the exemption | Management’s report |
Thresholds are set in SEC rules; confirm your status with your auditor and counsel.
When it matters for buyers
- When preparing for an IPO. IT controls need to be designed, documented and operating before the first audit.
- When choosing ERP, payroll, cloud or data center providers. Ask for a SOC 1 report scoped to the service.
- When moving financial systems to the cloud. Access and change controls need to be rebuilt for the new environment.
- When an acquisition brings in another company’s systems. They usually have to meet the acquirer’s control standards.
Our governance, risk and compliance overview covers advisors and tools for control testing, and our privileged access management overview covers one of the controls auditors look at most closely.
Questions to ask vendors
- Do you provide a SOC 1 Type II report, and does it cover the specific service and locations we’d use?
- What period does it cover, and will you provide bridge letters for the gap to our year end?
- Which complementary user entity controls does the report expect us to operate?
- How do you control and log privileged access to systems holding our financial data?
- How are changes to the service approved, tested and communicated to us?
- Can we export the access and change logs our auditors will ask for?
How it differs from SOC 2
SOC 2 is an attestation report on a service organization’s controls for security and related criteria, requested by customers. SOX is a law that applies to public companies. The report that supports SOX reliance on a vendor is usually SOC 1, which focuses on controls relevant to customers’ financial reporting, not SOC 2. Many providers offer both. SOX’s access controls overlap with identity and access management (IAM), and financial institutions often face SOX alongside the Gramm-Leach-Bliley Act (GLBA). A governance, risk and compliance (GRC) program usually maps SOX controls together with other data security compliance requirements.
